| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability in uMailServer, please report it responsibly.
Please do not open public issues for security vulnerabilities.
Instead, please email: security@umailserver.com
Include the following information:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will:
- Acknowledge receipt within 48 hours
- Provide a timeline for a fix
- Credit you in the security advisory (unless you prefer anonymity)
- bcrypt password hashing (cost 12)
- Automatic TLS with Let's Encrypt
- SPF, DKIM, DMARC verification
- Rate limiting and brute force protection
- Input validation and sanitization
- Sandboxed HTML email rendering